Health Services Agency
bd_67348f2bdea69711 · schema v1 · pii pii-v1
Full breach record for Health Services Agency →Stanislaus County Health Services Agency reported a data breach involving protected health information (PHI) of its patients. The incident occurred at Aesto, LLC, a third-party vendor providing healthcare data migration and archiving services. Between December 2 and December 18, 2025, an unauthorized actor accessed PHI stored on Aesto's AWS infrastructure. The breach was discovered on December 18, 2025. Affected data includes full names and other health-related information. The agency notified the California Attorney General and affected individuals, offering identity theft protection services.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 2, 2025
Begins
Dec 18, 2025
Discovered
Jul 31, 2026
Filed
vs. sector median
+20 wks slower
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.